IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2015-10-09T14:00:00
Updated: 2016-12-06T18:57:01
Reserved: 2015-07-01T00:00:00
Link: CVE-2015-5234
JSON object: View
NVD Information
Status : Modified
Published: 2015-10-09T14:59:01.843
Modified: 2018-10-30T16:27:35.843
Link: CVE-2015-5234
JSON object: View
Redhat Information
No data.
CWE